URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: hajifaraj.ir
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-20 09:49:11 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-29 11:26:16 89.39.208.131cp122.unitedhost.infoNot listedAS204213 netmihan- IRyes
2020-08-20 09:49:12 138.201.141.77static.77.141.201.138.clients.your-server.deNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-20 09:49:12http://hajifaraj.ir/hajifaraj.ir/sites/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-20 15:23:14123ba583a9ad8848142156dd3e087a6d746ba164b07681d1a0893f45af6b7cbadocHeodo
2020-08-20 14:53:3002beded3bf97160a812d8bd478ac0f798e12c3b82c464bb8429c8a5d78ae0c3cdocHeodo
2020-08-20 14:31:34713e8a1be959b7dd6086d6db1966d903ebbcc7c9b3df5fe7d7d5e0033bcf4f4fdocHeodo
2020-08-20 14:09:553d3214a91f8fa0fe6c54f9de7d331ac31f1a562aa0c0b0e33fb5aef75163ff95docHeodo
2020-08-20 13:47:012704479bb70ab89f699b958bff80a648c4c3b03d3875afd7cf5d833fd625e037docHeodo
2020-08-20 13:26:5362aaaf61f90d1c3f0c657fb7c0698dc7e72492a3e762c2161612a93b9ffe2aa1docHeodo
2020-08-20 12:54:2429b52f890109db1441bb1fab0d062383405b49e076d6f8c04c40644a9cfda15fdocHeodo
2020-08-20 12:44:24af814b93d391c55cf505da148f1c2115049dda290499697b1b91cf51e099828edocHeodo
2020-08-20 12:29:1466adaecff904f859044c0d2aacc5bf77afc7928a3827c0e75dda7e79c0c29601docHeodo
2020-08-20 12:11:0473bfcb9214b001594d3b0d3cc9c11c8ae9b0c2f57e4b75b8772cdad41a7e3c28docHeodo
2020-08-20 11:43:120fc24e52f38dc2987ac5826abe05dc4861ea6207d44b82b557222611f19173c7docHeodo
2020-08-20 11:17:13ab47a062dbbd97fae72fe297e5cffaea9d96c74395b5e6e3113c55364df5f6a1docHeodo
2020-08-20 10:55:506999b90afceb089b399c074269f52600ddb3d7aee434cfba9a1896c8213f4df1docHeodo
2020-08-20 10:34:52568471d2d31e15f9b46076ae0167cdda7da49957b7cb120d330a0e450bc2c7f3docHeodo
2020-08-20 10:07:02cc9254149ac0a5f25e859e00fd4ae509b05a23e42d49708d4c0a15e4628b1c66docHeodo
2020-08-20 09:49:12c4d72dd24ca207058b0934dd1e28840b1c2ba319b959da0132aca80464d52475docHeodo